Netskope Extension Risk

Detail view · rubric v3.6
← Back to catalog

Frogtastic

alkfljfjkpiccfgbeocbbjjladigcleg
Risk Score
4.33
Risk Level: Medium
Recommendation: 🟡 MEDIUM RISK — review
Category Entertainment
Installs 18
Rating 5.0
Last updated 2026-04-17 (4 months ago)
Manifest version MV3
CSP present ✅ yes
Developer nadejdinv@gmail.com
Verified publisher ❌ no
Featured by Google ❌ no
Privacy policy link
Web Store open ↗

Top Risks

  • Privacy policy hosted on cloudapi.stream CDN, not scoped to this extension, does not specify data collection — privacy pillar maxed.
  • Uninstall URL hijack flag set — classic monetization shell telltale even with null target.
  • jquery@3.2.1 bundles 3 medium CVEs (XSS); unfixed, version below fixed_in=3.5.0.
  • Free-webmail dev (gmail), no developer name, no verified publisher — identity unverifiable.
  • 10 external JS hosts referenced in CRX including goo.gl short-linker and unknown CDNs.

Evidence

  • uninstall_url_hijack crx uninstall_url_hijack=true; target null but flag present — monetization shell indicator (+3.0 webstore).
  • privacy_policy_not_scoped store Policy at cdn.cloudapi.stream: scope_extension=false, data_collection=false, third_party_sharing=true → +9.0 base + capped at 10.
  • free_webmail_no_dev_name store developer_email=nadejdinv@gmail.com, developer_name empty, no verified publisher → reputation floor 7.5.
  • jquery_cve_medium_x3 crx jquery@3.2.1 has CVE-2019-11358, CVE-2020-11022, CVE-2020-11023 (all medium, unfixed in bundled version).
  • external_js_hosts_10 crx 10 distinct external hosts in js_external_hosts incl. goo.gl, bnjmnt4n.now.sh, cloudapi.stream.
  • sandbox_csp_unsafe_eval manifest Sandbox CSP includes unsafe-inline and unsafe-eval on script-src — elevated XSS risk in sandbox context.
  • install_url_hijack crx install_url_hijack=true, target=popup/index.html (internal) — lower risk but pattern matches shell.
  • obfuscation_zero_code_clean crx obfuscation_score=0.0, code_findings_raw empty — no active exfil signals detected.

CVE Exposures (3)

CVELibrarySeverity Fixed inSummary
CVE-2019-11358 jquery@3.2.1 moderate 3.4.0 XSS in jQuery as used in Drupal, Backdrop CMS, and other products
CVE-2020-11022 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery
CVE-2020-11023 jquery@3.2.1 moderate 3.5.0 Potential XSS vulnerability in jQuery

Permissions Breakdown

  • uninstall_url_hijack high Extension sets uninstall URL redirect — a classic monetization/tracking shell signal.
  • install_url_hijack medium onInstalled opens popup/index.html internally; low direct risk but confirms hijack pattern.

Pillar Scores

Permissions1.00
Reputation7.50
Network3.00
Webstore6.50
Maintenance1.50
Privacy10.00
Code Quality0.00
CVE Exposure3.00

Bookkeeping

Rubric v3.6
Scored at 2026-08-28 08:54
Listing SHA 9a642df76e2b…
Force block — not fired
Score recovered no
Elapsed